DMCA Section 1201: The Anti-Circumvention Law, Explained

DMCA 1201 explained: circumvention vs. trafficking bans, the 2024 exemptions, repair and security research carve-outs, and the infringement nexus split.

Technician repairing a game console motherboard with a screwdriver at a workbench
Section 1201 makes breaking a digital lock its own violation, separate from copyright infringement. Whether your repair, research, or jailbreak is legal often turns on a triennial exemption list. Shutterstock
Educational guide, not legal advice. This article explains general legal concepts and is not a substitute for advice from an attorney licensed in your jurisdiction. Reading it does not create an attorney–client relationship.
Quick answer: [17 U.S.C. § 1201](https://www.law.cornell.edu/uscode/text/17/1201) is the DMCA's anti-circumvention law. It contains three distinct prohibitions: circumventing a technological measure that controls access to a copyrighted work (§ 1201(a)(1)), trafficking in tools that circumvent access controls (§ 1201(a)(2)), and trafficking in tools that circumvent copy controls protecting a copyright owner's rights (§ 1201(b)). Breaking the lock is a separate violation from infringing the copyright, and in some circuits it requires no infringement at all. Relief comes from permanent statutory carve-outs (reverse engineering for interoperability, encryption research, security testing) and from temporary exemptions the Librarian of Congress adopts every three years, most recently in October 2024. This is general education, not legal advice.

You jailbroke a device, bypassed a dongle check, scraped data from behind a login, or built a tool that unlocks someone else’s format, and someone mentioned “DMCA 1201.” This is not the takedown-notice part of the DMCA. Section 512, covered in our guide to DMCA takedowns, governs getting content removed from platforms. Section 1201 is different: it regulates digital locks. It makes circumventing certain technological protection measures, and trafficking in circumvention tools, unlawful in themselves, on top of and independent of copyright infringement. For software companies the statute cuts both ways: it protects your DRM and license checks, and it constrains how you interact with everyone else’s. This guide sits within our pillar on open source and software IP.

What Section 1201 actually prohibits

The statute draws two distinctions that decide most cases: access controls versus rights (copy) controls, and conduct versus trafficking.

ProvisionWhat it bansType of measure
§ 1201(a)(1)The act of circumventingAccess controls (encryption, authentication, license checks)
§ 1201(a)(2)Making or trafficking in circumvention toolsAccess controls
§ 1201(b)(1)Making or trafficking in circumvention toolsRights controls (copy protection, usage restrictions)

Section 1201(a)(1)(A) prohibits circumventing “a technological measure that effectively controls access to a work protected under this title.” Circumventing means “to descramble a scrambled work, to decrypt an encrypted work, or otherwise to avoid, bypass, remove, deactivate, or impair a technological measure.” Think CSS encryption on DVDs, authentication servers for online games, firmware locks on devices.

Sections 1201(a)(2) and 1201(b)(1) are the anti-trafficking rules. They prohibit manufacturing, importing, offering to the public, or trafficking in any technology, product, or service that is primarily designed for circumvention, has only limited commercially significant purpose other than circumvention, or is marketed for circumvention. The (a)(2) version targets tools that defeat access controls; the (b)(1) version targets tools that defeat measures protecting “a right of a copyright owner,” such as copy controls.

Notice the asymmetry: there is no conduct ban on circumventing a rights control yourself. Congress left that gap deliberately, because if you defeat a copy control and then actually infringe, ordinary copyright law already reaches you. The act-of-circumvention ban applies only to access controls, and that is where the triennial exemptions operate.

This is the deepest fight in § 1201 law, and it remains unresolved at the circuit level. Section 1201(c)(1) says that nothing in the section “shall affect rights, remedies, limitations, or defenses to copyright infringement, including fair use.” So what happens when someone circumvents a lock for a purpose that infringes nothing?

The Federal Circuit answered in Chamberlain v. Skylink, 381 F.3d 1178 (Fed. Cir. 2004), the garage-door-opener case: § 1201 liability requires a nexus to copyright infringement. A universal remote that interoperated with Chamberlain’s openers did not facilitate any infringement, so there was no DMCA violation. On that reading, the statute cannot be used simply to lock out aftermarket competitors.

The Ninth Circuit rejected that reading in MDY Industries v. Blizzard, 629 F.3d 928 (9th Cir. 2010), the World of Warcraft bot case. It held that § 1201(a) creates a new anti-circumvention right independent of infringement: no nexus required. A tool that evaded Blizzard’s Warden scan violated § 1201(a)(2) even though running a bot infringed no exclusive right.

The split matters enormously for anyone building interoperable products. In the Ninth Circuit (home to most of the software industry), defeating an access control can be unlawful even when everything you do afterward is noninfringing. Courts following Chamberlain’s logic ask what the lock is actually protecting. Plan around the stricter rule.

The permanent exemptions built into the statute

Congress hard-coded several carve-outs that never expire. The ones that matter most in practice:

  • Reverse engineering for interoperability, § 1201(f). A person who lawfully obtained the right to use a copy of a computer program may circumvent to identify and analyze the elements necessary to make an independently created program interoperate, where that information is not otherwise readily available and the acts do not infringe. This is the exemption clean-room interoperability projects live under. It is narrow, and it does not authorize shipping a circumvention tool to the general public except for the interoperability purpose.
  • Encryption research, § 1201(g). Good-faith research into flaws and vulnerabilities of encryption technologies, on lawfully obtained copies, with an effort to obtain authorization.
  • Security testing, § 1201(j). Accessing a computer or network, with authorization of its owner or operator, solely to test, investigate, or correct a security flaw or vulnerability.
  • Protection of personally identifying information, § 1201(i), plus provisions for law enforcement (§ 1201(e)), nonprofit libraries assessing acquisitions (§ 1201(d)), and parental controls (§ 1201(h)).

The research and testing exemptions carry multi-factor conditions that courts and prosecutors read closely. They are real, but they are not blanket permission slips, which is why the security community keeps returning to the triennial rulemaking for broader cover.

The triennial exemptions: where the law stands in 2026

Because Congress knew a flat circumvention ban would burn legitimate users, § 1201(a)(1)(C) directs the Librarian of Congress, on the Register of Copyrights’ recommendation, to adopt temporary exemptions every three years for classes of works where the ban is adversely affecting noninfringing uses.

The ninth triennial rulemaking concluded with a final rule effective October 28, 2024. The Register recommended renewal of essentially every existing exemption for which a renewal petition was filed, and the Librarian adopted several changes:

  • Renewed: repair and diagnosis of motorized land vehicles and marine vessels, repair of consumer devices and medical systems, jailbreaking smartphones, tablets, smart TVs, and voice assistants, good-faith security research on lawfully acquired devices, preservation of software and video games by libraries and archives, and unlocking of used cellphones.
  • Expanded: the text and data mining exemptions for scholarly research (allowing researchers at other nonprofit institutions access to existing corpora under security safeguards) and the educational audiovisual exemptions.
  • New: circumvention to diagnose, maintain, and repair retail-level commercial food preparation equipment (the exemption prompted by perpetually broken soft-serve machines) and an exemption allowing vehicle owners to access their own operational and telematics data.
  • Denied: a proposed exemption for AI trustworthiness research on generative AI platforms. The Office concluded the obstacles researchers face come from providers’ terms of service, not from technological protection measures, so a § 1201 exemption would not help.

These exemptions run through October 2027. The tenth triennial cycle is now underway: the Copyright Office opened it on June 9, 2026, with petitions for renewals and new exemptions due August 24, 2026. If your business depends on an exemption (repair, research, preservation, accessibility), the renewal window is happening right now.

Two limits to remember. Exemptions cover only the act of circumvention under § 1201(a)(1), never the trafficking bans, so a repair shop may circumvent under an exemption while the company selling it a purpose-built unlocking tool can still face § 1201(a)(2) exposure. And exemptions are class-specific: read the actual regulatory text, because the conditions (lawfully acquired device, good-faith purpose, no violation of other laws) are part of the exemption.

What are the penalties for violating § 1201?

Section 1203 provides a civil action for “any person injured” by a violation: injunctions, actual damages plus profits, or statutory damages of $200 to $2,500 per act of circumvention or per device, product, or service trafficked. Repeat violations within three years of a prior judgment can be trebled; innocent violations can be reduced. Section 1204 adds criminal liability for willful violations for commercial advantage or private financial gain, up to $500,000 or five years’ imprisonment for a first offense.

Because each device sold can count separately, trafficking claims scale fast. A defendant who ships ten thousand mod chips is not facing one violation.

What this means for developers, researchers, and repair shops

  1. Interoperating with a protected system? Map your conduct to § 1201(f) before you start: lawful copy, interoperability purpose, information not otherwise available, contemporaneous documentation. In the Ninth Circuit, do not count on “we infringed nothing” as a defense after MDY.
  2. Shipping anything that unlocks, bypasses, or patches someone else’s software? The trafficking provisions judge your tool by its design, commercial purpose, and marketing. How you advertise a product can convert it into a circumvention device.
  3. Doing security research? Layer your protections: § 1201(j), the renewed security research exemption, authorization from the system owner, and a written scope. The permanent exemptions alone are narrower than most researchers assume.
  4. Running DRM or license checks on your own product? Section 1201 gives you a claim against circumvention that copyright alone would not, but Chamberlain warns against using it purely to shut out aftermarket competition, and fair use pressures are growing at the rulemaking level. How you protect the code itself is covered in how to protect source code.
  5. Received a § 1201 cease and desist? Do not confuse it with a takedown notice, and do not respond with a DMCA counter-notice; that mechanism belongs to § 512 and has no application here. Circumvention claims need a litigation-grade response.

For how courts have applied all of this, browse the circumvention case archive.

The bottom line

Section 1201 makes the digital lock itself a legally protected object: circumventing an access control violates § 1201(a)(1), and building or distributing tools that defeat access or copy controls violates the trafficking bans, in the Ninth Circuit even without any copyright infringement. Your safe paths run through the permanent exemptions (interoperability, encryption research, security testing) and the triennial exemption list, which was refreshed in October 2024 and is being renegotiated right now for 2027. Before you bypass anyone’s protection measure, or ship a tool that does, identify the exact exemption you are standing on and satisfy its conditions.


This guide is for educational purposes only and is not legal advice. IP outcomes turn on specific facts; talk to a licensed attorney about your situation.

Frequently asked questions

Is it illegal to circumvent DRM even if I am not pirating anything?

Often yes, under 17 U.S.C. § 1201(a)(1). The statute prohibits circumventing a technological measure that effectively controls access to a copyrighted work, and in the Ninth Circuit's MDY v. Blizzard reading, that violation does not require any copyright infringement at all. Your protection comes from two places: the permanent statutory exemptions (such as reverse engineering for interoperability under § 1201(f) and security testing under § 1201(j)) and the temporary exemptions the Librarian of Congress adopts every three years, which currently cover activities like device repair, jailbreaking, and good-faith security research. If your activity fits an exemption, the conduct ban does not apply. If it does not, the fact that you never copied anything may not save you.

Does DMCA 1201 make reverse engineering illegal?

Not categorically. Section 1201(f) is a permanent exemption that permits a person who has lawfully obtained the right to use a copy of a computer program to circumvent an access control for the sole purpose of identifying and analyzing elements necessary to achieve interoperability of an independently created program, to the extent that information is not otherwise readily available and the acts do not constitute infringement. The exemption is narrow: it covers interoperability analysis, not cloning a competitor's product, and courts have read its conditions strictly. Traditional reverse engineering that never touches a technological protection measure is outside § 1201 entirely, though it can still raise contract (EULA) and trade secret questions.

What is the DMCA triennial exemption rulemaking?

Congress built a safety valve into § 1201(a)(1): every three years the Librarian of Congress, on the recommendation of the Register of Copyrights, adopts temporary exemptions for classes of works where the circumvention ban is adversely affecting noninfringing uses. The ninth rulemaking concluded in October 2024, renewing essentially all prior exemptions (vehicle and device repair, jailbreaking, security research, game preservation, text and data mining) and adding new ones, including repair of retail-level commercial food preparation equipment. The tenth cycle opened in June 2026 and will conclude with a new rule in late 2027. Exemptions cover only the act of circumvention, not the trafficking bans, and they expire unless renewed.

What are the penalties for violating Section 1201?

Section 1203 gives a civil cause of action to any person injured by a violation. A plaintiff can elect actual damages plus the violator's profits, or statutory damages of $200 to $2,500 per act of circumvention or per device or service trafficked, with treble damages available for repeat violations within three years of a prior judgment and reductions possible for innocent violations. Separately, § 1204 makes willful violations committed for commercial advantage or private financial gain a federal crime, punishable for a first offense by up to $500,000 in fines or five years in prison. Most disputes founders and developers see are civil, and they frequently arrive bundled with copyright, contract, and CFAA claims.

Lidiia Levitska
About the Author

Lidiia Levitska

International Intellectual Property Attorney

Lidiia Levitska focuses on intellectual property dispute resolution, policy, and advisory work across international institutions and government bodies. From 2021 to 2025 she served at the World Intellectual Property Organization (WIPO), managing arbitration cases and overseeing compliance with the Uniform Domain-Name Dispute-Resolution Policy (UDRP), and earlier led IP policy research as a Senior Policy Officer at the American Chamber of Commerce in Ukraine. She holds an LL.M. in International Intellectual Property Law from Chicago-Kent College of Law and an M.A. in Information Technology Law from the University of Tartu, and was admitted to the Ukrainian Bar in 2019.

More about Lidiia →